Live incidents
—
Checking…
By kind
Loading…
The log · newest first
Loading detections…
— · JSON API · live incidents only · how the ranks work
Detection, incident, and the difference.
New, 24 September 2026: drain_pattern. A payment at least five times the agent’s previous largest, at least $250, to an address it had never paid, after at least three earlier payments. It is the shape a drained agent wallet leaves, and also the shape of a legitimate one-off purchase, so it is always a detection for a human to read, never an incident, and the agent is never named publicly. The reasoning →
A detection is an occurrence: it happened at a time, we can point at the evidence, and a reader could in principle have watched it happen. A detector that fired on a state would turn this page into a scoreboard, and a scoreboard of low scores is worth nothing to anybody. "This agent has never answered a probe" sits on the edge — it is a state — so it only becomes a detection after a streak of failures with no success ever recorded, which makes it an event about our own repeated attempts rather than a verdict on the agent.
An incident is a detection that is also a harm, and recent. Three kinds qualify: a retry storm, where an agent pays the same counterparty over and over and somebody is paying the fees for every attempt; an identity that changed owner under a binding people rely on, so the history they trust now belongs to somebody else; and signing delegated to an implementation nobody has vetted. Each counts as live for 72 hours, then stays in the log as a detection.
A mint burst is never an incident, however large. One address minting hundreds of registrations in an hour is exactly what a platform issuing identities for its users looks like. It is worth logging because it changes what a registration count means — the headline is measuring a script, not an ecosystem — but it harms nobody. This page called it a sybil burst until September 2026, and that was wrong: sybil asserts intent, and our own definition says the opposite.
Detectors that are armed and currently silent still matter. god_key_unknown_7702 fires when a wallet delegates to an implementation outside a curated allowlist, and that allowlist ships empty on purpose — until a human has read a contract and can say why it belongs there, calling an unknown implementation a god key would be a guess, and this site does not publish guesses. It reports nothing today, and that is the honest answer rather than a broken one.